Skip to content
Malware KONNI Uses AI for PowerShell Backdoors; Badbox 2.0 Botnet Investigated

Malware KONNI Uses AI for PowerShell Backdoors; Badbox 2.0 Botnet Investigated

First seen 2 Feb 2026, 17:45 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 22, 2026 at 11:13 UTC

Malware KONNI has adopted artificial intelligence to generate PowerShell backdoors, enhancing its capabilities in cyber attacks. The Badbox 2.0 botnet, believed to be weaponized in China, is reportedly being deployed in targeted espionage campaigns in India. Additionally, a new Android Trojan campaign is utilizing Hugging Face hosting for its RAT payload.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 203d ago How this analysis works

More articles in this cluster (33)

Following this threat?

Track Konni and Badbox 2.0 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed